falls within the scope of the Act and as such, the remedies are general to all kinds of
violations of protection of personal data.
A complaint on interference with protection of personal information by a data
subject may cause the Regulator to conduct a pre-investigation or a full investigation.
129 The Regulator may refer the complaint to the enforcement committee.
130 At
the end of the investigation, the Regulator may decide to take no action.
131 The
Regulator may refer such complaint to the regulatory body to handle if such is within
the jurisdiction of another regulatory body.
132 The Regulator could also cause a
settlement between the parties if it appears that it is possible to do so.
133 The
Regulator can approach the court for a warrant to enter, search and seize property.
134
The Regulator can finally issue an enforcement notice requiring an infringer or a
responsible party to take or refrain from taking specific steps or to stop processing
based on the notice.
135 Other remedies especially civil and criminal are discussed
below. However, these remedies can only be carried out with the assistance of the
courts.
Section 73 of the POPI Act considers non-compliance with the rules on electronic
communications for direct marketing purposes as an interference with the protection
of personal information and could be a ground for civil action for damages based on
section 99. Details are provided below.
As mentioned below, a breach of the rules on security of personal data processed
electronically (which is among the conditions for lawful processing) is considered as
an interference with the protection of personal information
136 and this could be a
ground for action in court for damages.
137 The Regulator may also impose an
administrative fine.
138
As mentioned earlier, the general data protection legislation in South Africa is yet
to fully come into force. Hence, although the main supervisory body (Information
Regulator) has been set up, it is yet to be fully functioning. The penalty for the breach
of the provision of the POPI Act, if considered criminal, may be up to 12 months to
10 years with or without fine.
139 Furthermore, it is provided that the Information
Regulator has the power to impose, in lieu of a criminal action, an administrative fine
of up to R10 million (10 Million South African Rands).
140 Some commentators
129 See Section 76(1) of the POPI Act.
130 Section 76(1) of the POPI Act.
131 Section 77 of the POPI Act.
132 Section 78(1) of the POPI Act.
133 Section 80 of the POPI Act.
134 Section 82 of the POPI Act.
135 Section 95 of the POPI Act.
136 Section 73 of the POPI Act.
137 Section 99 of the POPI Act.
138 Section 109 of the POPI Act.
139 Section 107 of the POPI Act.
140 Section 109(2) (c) of the POPI Act.
366
L. A. Abdulrauf
violations of protection of personal data.
A complaint on interference with protection of personal information by a data
subject may cause the Regulator to conduct a pre-investigation or a full investigation.
129 The Regulator may refer the complaint to the enforcement committee.
130 At
the end of the investigation, the Regulator may decide to take no action.
131 The
Regulator may refer such complaint to the regulatory body to handle if such is within
the jurisdiction of another regulatory body.
132 The Regulator could also cause a
settlement between the parties if it appears that it is possible to do so.
133 The
Regulator can approach the court for a warrant to enter, search and seize property.
134
The Regulator can finally issue an enforcement notice requiring an infringer or a
responsible party to take or refrain from taking specific steps or to stop processing
based on the notice.
135 Other remedies especially civil and criminal are discussed
below. However, these remedies can only be carried out with the assistance of the
courts.
Section 73 of the POPI Act considers non-compliance with the rules on electronic
communications for direct marketing purposes as an interference with the protection
of personal information and could be a ground for civil action for damages based on
section 99. Details are provided below.
As mentioned below, a breach of the rules on security of personal data processed
electronically (which is among the conditions for lawful processing) is considered as
an interference with the protection of personal information
136 and this could be a
ground for action in court for damages.
137 The Regulator may also impose an
administrative fine.
138
As mentioned earlier, the general data protection legislation in South Africa is yet
to fully come into force. Hence, although the main supervisory body (Information
Regulator) has been set up, it is yet to be fully functioning. The penalty for the breach
of the provision of the POPI Act, if considered criminal, may be up to 12 months to
10 years with or without fine.
139 Furthermore, it is provided that the Information
Regulator has the power to impose, in lieu of a criminal action, an administrative fine
of up to R10 million (10 Million South African Rands).
140 Some commentators
129 See Section 76(1) of the POPI Act.
130 Section 76(1) of the POPI Act.
131 Section 77 of the POPI Act.
132 Section 78(1) of the POPI Act.
133 Section 80 of the POPI Act.
134 Section 82 of the POPI Act.
135 Section 95 of the POPI Act.
136 Section 73 of the POPI Act.
137 Section 99 of the POPI Act.
138 Section 109 of the POPI Act.
139 Section 107 of the POPI Act.
140 Section 109(2) (c) of the POPI Act.
366
L. A. Abdulrauf
